Malicious PDF — malware analysis report

Static analysis result for SHA-256 ecd52d905a0ca749…

MALICIOUS

PDF

15.9 KB Created: 2019-09-27 13:33:39 +01:00 Authoring application: mPDF 5.7
MD5: 693dce1d153e706d33da835d908bb81e SHA-1: 97233adda1320aef6c23d84ad9c4d972990b8da8 SHA-256: ecd52d905a0ca7492b2005783eb48457cf28dd6274765a5757875c48d36882b3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, forming a link farm. This technique is often used to obscure the true malicious intent or to distribute malicious content indirectly. The primary heuristic indicates a critical finding related to this link farm. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3737738737733738/Playing-with-Matches-Playing-with-Matches-1-by-Lee-Strauss.pdf
    • http://cefasfese.4pu.com/1730737738730732734/Playing-with-Matches-The-Matchmaker-Project-2-by-N-G-Simsion.pdf
    • http://cefasfese.4pu.com/4735735733731733/A-Piece-of-Blue-String-Playing-with-Matches-0-5-by-Lee-Strauss.pdf
    • http://cefasfese.4pu.com/1737730736739736/Playing-by-His-Rules-Playing-2-by-Glenda-Horsfall.pdf
    • http://cefasfese.4pu.com/6739732738738739/Playing-Dirty-Playing-to-Win-3-by-Alix-Nichols.pdf
    • http://cefasfese.4pu.com/1730735734734731739/Thoughtless-Acts-Observations-on-Intuitive-Design-by-Jane-Fulton-Suri.pdf
    • http://cefasfese.4pu.com/1730730738730739733/Advances-in-Neuromorphic-Hardware-Exploiting-Emerging-Nanoscale-Devices-by-Manan-Suri.pdf
    • http://cefasfese.4pu.com/7736736734735/Seeds-for-Change-The-Lives-and-Work-of-Suri-and-Edda-Sehgal-by-Marly-Cornell.pdf
    • http://cefasfese.4pu.com/8739736735738/Playing-for-First-Playing-for-First-1-by-Chris-Paynter.pdf
    • http://cefasfese.4pu.com/6739732738734738/Playing-for-Keeps-Playing-to-Win-2-by-Alix-Nichols.pdf
    • http://cefasfese.4pu.com/4733734736739738/Once-We-Won-Matches-Cambridge-Fellows-7-5-by-Charlie-Cochrane.pdf
    • http://cefasfese.4pu.com/9739732732731732/A-Lawman-for-Christmas-Smoky-Mountain-Matches-12-by-Karen-Kirst.pdf
    • http://cefasfese.4pu.com/9739732732730737/The-Husband-Hunt-Smoky-Mountain-Matches-4-by-Karen-Kirst.pdf
    • http://cefasfese.4pu.com/4739739738730738/The-Bachelor-s-Homecoming-Smoky-Mountain-Matches-7-by-Karen-Kirst.pdf
    • http://cefasfese.4pu.com/7732733739734736/The-Texan-s-Inherited-Family-Bachelor-List-Matches-1-by-Noelle-Marchand.pdf
    • http://cefasfese.4pu.com/7732733739735730/The-Texan-s-Courtship-Lessons-Bachelor-List-Matches-2-by-Noelle-Marchand.pdf
    • http://cefasfese.4pu.com/7732733739734737/The-Texan-s-Engagement-Agreement-Bachelor-List-Matches-3-by-Noelle-Marchand.pdf
    • http://cefasfese.4pu.com/3734738730/Playing-with-Monsters-Playing-with-Monsters-1-by-Amelia-Hutchins.pdf
    • http://cefasfese.4pu.com/9739732732731734/His-Mountain-Miss-Smoky-Mountain-Matches-3-by-Karen-Kirst.pdf
    • http://cefasfese.4pu.com/2733734738734736/And-God-Belched-by-Rob-Rosen.pdf
    • http://cefasfese.4pu.com/8739736735738/Playing-for-First-Playing-for-First-1-by-Chris-Paynter